Executive brief
Adobe Experience Manager, a content management and digital experience platform used by enterprises, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in their browser context, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
Technical details
The vulnerability is a DOM-based cross-site scripting flaw in Adobe Experience Manager that allows an attacker to manipulate the DOM environment and execute malicious JavaScript. Exploitation requires user interaction: a victim must visit an attacker-controlled or compromised webpage that contains the crafted payload. The attack occurs client-side within the victim's browser, operating within the security context of the Experience Manager application. An attacker can execute arbitrary code, potentially compromising user sessions, stealing sensitive data, or performing unauthorized administrative actions.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed